Suppr超能文献

通过动态访问控制策略转换实现分布式临床数据共享。

Distributed clinical data sharing via dynamic access-control policy transformation.

作者信息

Rezaeibagha Fatemeh, Mu Yi

机构信息

Centre for Computer and Information Security Research, School of Computing and Information Technology, University of Wollongong, NSW, Australia.

Centre for Computer and Information Security Research, School of Computing and Information Technology, University of Wollongong, NSW, Australia.

出版信息

Int J Med Inform. 2016 May;89:25-31. doi: 10.1016/j.ijmedinf.2016.02.002. Epub 2016 Feb 12.

Abstract

BACKGROUND

Data sharing in electronic health record (EHR) systems is important for improving the quality of healthcare delivery. Data sharing, however, has raised some security and privacy concerns because healthcare data could be potentially accessible by a variety of users, which could lead to privacy exposure of patients. Without addressing this issue, large-scale adoption and sharing of EHR data are impractical. The traditional solution to the problem is via encryption. Although encryption can be applied to access control, it is not applicable for complex EHR systems that require multiple domains (e.g. public and private clouds) with various access requirements.

OBJECTIVES

This study was carried out to address the security and privacy issues of EHR data sharing with our novel access-control mechanism, which captures the scenario of the hybrid clouds and need of access-control policy transformation, to provide secure and privacy-preserving data sharing among different healthcare enterprises.

METHODS

We introduce an access-control mechanism with some cryptographic building blocks and present a novel approach for secure EHR data sharing and access-control policy transformation in EHR systems for hybrid clouds.

RESULTS

We propose a useful data sharing system for healthcare providers to handle various EHR users who have various access privileges in different cloud environments. A systematic study has been conducted on data sharing in EHR systems to provide a solution to the security and privacy issues.

CONCLUSIONS

In conclusion, we introduce an access-control method for privacy protection of EHRs and EHR policy transformation that allows an EHR access-control policy to be transformed from a private cloud to a public cloud. This method has never been studied previously in the literature. Furthermore, we provide a protocol to demonstrate policy transformation as an application scenario.

摘要

背景

电子健康记录(EHR)系统中的数据共享对于提高医疗服务质量至关重要。然而,数据共享引发了一些安全和隐私问题,因为医疗数据可能会被各类用户访问,这可能导致患者隐私泄露。如果不解决这个问题,大规模采用和共享EHR数据是不切实际的。传统的解决方法是通过加密。虽然加密可用于访问控制,但它不适用于需要多个具有不同访问要求的域(如公共云和私有云)的复杂EHR系统。

目的

本研究旨在通过我们新颖的访问控制机制解决EHR数据共享的安全和隐私问题,该机制捕捉了混合云场景以及访问控制策略转换的需求,以在不同医疗企业之间提供安全且保护隐私的数据共享。

方法

我们引入一种带有一些加密构建块的访问控制机制,并提出一种在混合云的EHR系统中进行安全EHR数据共享和访问控制策略转换的新颖方法。

结果

我们为医疗服务提供者提出了一个有用的数据共享系统,以处理在不同云环境中具有不同访问权限的各类EHR用户。已对EHR系统中的数据共享进行了系统研究,以提供安全和隐私问题的解决方案。

结论

总之,我们引入了一种用于EHR隐私保护和EHR策略转换的访问控制方法,该方法允许将EHR访问控制策略从私有云转换到公共云。该方法此前在文献中从未被研究过。此外,我们提供了一个协议来演示作为应用场景的策略转换。

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验